ci: check the Pin against Upstream with make verify-pin before the cached build #26

Merged
piscis merged 4 commits from piscis/forgejo-25-verify-pin into main 2026-09-30 15:29:26 +00:00
Owner

Closes #25

What

  • make verify-pin resolves the Upstream Version's tag on Upstream with git ls-remote and compares it with the Pin's UPSTREAM_COMMIT. It uses the peeled ref refs/tags/<version>^{} (annotated tags) and falls back to refs/tags/<version> (lightweight tags). It fails if the tag doesn't exist, and on a mismatch with the same message as the Dockerfile check.
  • The Upstream URL is defined once, as UPSTREAM_REPO in the Makefile. make build passes it as --build-arg UPSTREAM_REPO=..., so the two checks read the same repo. The Dockerfile keeps its ARG UPSTREAM_REPO default for a plain docker build.
  • ci runs make verify-pin in the job container before "Build the Image". It doesn't use the build cache, so a moved tag turns CI red even when the build is cached.
  • The Dockerfile check stays: it still protects uncached and local builds.

Verified

Locally:

  • make verify-pin with the real Pin passes: Upstream tag v3.2.0 resolves to e30bb7e…, as the Pin expects.
  • UPSTREAM_COMMIT=0000… fails with the Dockerfile's wording. UPSTREAM_VERSION=v9.9.9 fails with Upstream tag v9.9.9 not found.
  • A lightweight tag in a local test repo passes (fallback to the plain ref).

In CI:

  • Run 29 (64d86e4): green with a warm cache. verify-pin passes, and the build's clone-and-verify step is CACHED, which is exactly the case #25 is about.
  • Run 30 (throwaway 3bdd5ad, UPSTREAM_COMMIT set to the tag object 931a525…): red at "Verify the Pin against Upstream", before any build ran:
    ERROR: Upstream tag v3.2.0 resolves to commit e30bb7e2e45c0e447506b5df1fe83ebce4b43944, but the Pin expects 931a525dc25dfef430c4bbee51728ad3795f7491.
    ERROR: The tag was moved or the Pin is wrong. Check https://git.b4mad.industries/agentic-forges/forgejo-mcp.git and update pin.env.
    make: *** [Makefile:41: verify-pin] Error 1
    
  • 3911410 reverts the throwaway commit (same pattern as 68e52e5/c76070e). Run 32 on it is green.

Follow-up: #7's publish workflow should run make verify-pin before building too (noted on #7).

Closes #25 ## What - `make verify-pin` resolves the Upstream Version's tag on Upstream with `git ls-remote` and compares it with the Pin's `UPSTREAM_COMMIT`. It uses the peeled ref `refs/tags/<version>^{}` (annotated tags) and falls back to `refs/tags/<version>` (lightweight tags). It fails if the tag doesn't exist, and on a mismatch with the same message as the Dockerfile check. - The Upstream URL is defined once, as `UPSTREAM_REPO` in the Makefile. `make build` passes it as `--build-arg UPSTREAM_REPO=...`, so the two checks read the same repo. The Dockerfile keeps its `ARG UPSTREAM_REPO` default for a plain `docker build`. - `ci` runs `make verify-pin` in the job container before "Build the Image". It doesn't use the build cache, so a moved tag turns CI red even when the build is cached. - The Dockerfile check stays: it still protects uncached and local builds. ## Verified Locally: - `make verify-pin` with the real Pin passes: `Upstream tag v3.2.0 resolves to e30bb7e…, as the Pin expects.` - `UPSTREAM_COMMIT=0000…` fails with the Dockerfile's wording. `UPSTREAM_VERSION=v9.9.9` fails with `Upstream tag v9.9.9 not found`. - A lightweight tag in a local test repo passes (fallback to the plain ref). In CI: - [Run 29](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/29) (64d86e4): green with a warm cache. `verify-pin` passes, and the build's clone-and-verify step is `CACHED`, which is exactly the case #25 is about. - [Run 30](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/30) (throwaway 3bdd5ad, `UPSTREAM_COMMIT` set to the tag object `931a525…`): **red at "Verify the Pin against Upstream"**, before any build ran: ``` ERROR: Upstream tag v3.2.0 resolves to commit e30bb7e2e45c0e447506b5df1fe83ebce4b43944, but the Pin expects 931a525dc25dfef430c4bbee51728ad3795f7491. ERROR: The tag was moved or the Pin is wrong. Check https://git.b4mad.industries/agentic-forges/forgejo-mcp.git and update pin.env. make: *** [Makefile:41: verify-pin] Error 1 ``` - 3911410 reverts the throwaway commit (same pattern as 68e52e5/c76070e). [Run 32](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/32) on it is green. Follow-up: #7's publish workflow should run `make verify-pin` before building too (noted on #7).
The Dockerfile's clone-and-verify step is cached by its command and build args, so CI
stayed green if Upstream moved the pinned tag. make verify-pin resolves the tag with
git ls-remote and runs in ci before the build. The Upstream URL is defined once in the
Makefile and passed to the build as UPSTREAM_REPO.
Rewrap the Makefile header
All checks were successful
ci / build (pull_request) Successful in 18s
64d86e4740
Revert the throwaway wrong UPSTREAM_COMMIT (3bdd5ad)
All checks were successful
ci / build (pull_request) Successful in 19s
3911410785
piscis merged commit d1939b9c72 into main 2026-09-30 15:29:26 +00:00
piscis deleted branch piscis/forgejo-25-verify-pin 2026-09-30 15:29:26 +00:00
Sign in to join this conversation.
No description provided.